Deleted Virus & edited reg...now can't start Win Update service

From: Dawn (anonymous_at_discussions.microsoft.com)
Date: 08/29/04

  • Next message: msnews.microsoft.com: "Re: Remote Shut Down Priviledges"
    Date: Sun, 29 Aug 2004 13:52:10 -0700
    
    

    I followed the following steps to remove a
    virus "w32.maddis.b"...
    I stopped the service:
    a. Click Start > Programs > Administrative Tools >
    Services.
    b. Right-Click "Windows Update."
    c. Set Startup type to "Disabled."
    d. Click Stop.
    Now after stopping the Windows Update & deleting the
    infected USRINIT.EXE & HELPER.DLL & then I went into the
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
    and the deleted the "Windows Update" key.
    In the removal instruction it also said to delete the
    value: "WindowsUpdate" = "%System%\USRINIT.EXE"in
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio
    n\Run but it wasn't there.
    I can't start it again the Windows Update again. I don't
    know if I need to though.
    I get "error 1058-The service cannot be started either
    because it is diabled or because it has no enabled devices
    associated with it". When I right click & try to gp into
    properties so I can enable it I get "Configoration
    Manager:A required entry in the registry is missing or an
    attempt to right to it has failed.
    Am I OK or do I need to set up the registry key for the
    windows update...If I do can some one give me details of
    what to do?

    Thanks
    Dawn


  • Next message: msnews.microsoft.com: "Re: Remote Shut Down Priviledges"

    Relevant Pages

    • NEW VIRUS ?
      ... MSOFT32.exe runs and takes up all CPU of the PC and it has spread very ... The infected PCs were trying to connect out ... A registry key exists in HKLM\SOFTWARE\MICROSOFT\WINDOWS\RUN ONCE. ... manually doing windows update on 150 PC s AHh! ...
      (microsoft.public.security.virus)
    • Re: Terminal Server 2003 - Manager not visible or accessible
      ... Start regedit and navigate to this registry key: ... Delete the "Placement" value and exit regedit. ... MCSE, CCEA, Microsoft MVP - Terminal Server ... > An additional symptom was that Windows Update would not run, ...
      (microsoft.public.windows.terminal_services)
    • Re: Turning on Windows Update Administrativly
      ... >> Network policy settings prevent you from using Windows Update to download ... >> Windows Update to download and install updates. ... > Under the registry key ...
      (microsoft.public.windowsxp.security_admin)
    • Re: XP not allowed to access updates
      ... Please delete the following registry key. ... This may be resolved by uninstalling the third party firewall. ... Windows Update as an excluded site on the firewall/proxy. ... "Miles" wrote in message ...
      (microsoft.public.windowsxp.security_admin)
    • RE: Code 8000FFFF
      ... Corrupted Windows Update Temporary folder ... Rename the Windows Update Softwaredistribution folder ... let's backup the registry key first. ...
      (microsoft.public.windowsupdate)